A Windows domain intrusion linked to Gentlemen ransomware affiliates has revealed how a single breach can quickly escalate into widespread issues.
Here are some indicators of compromise (IoCs): Type Indicator Description IP address 193.233.202.17 Primary staging, C2, Sliver, tunnelling, and registry-hive exfiltration server IP address 146.103.127.44 Secondary controller embedded in Go reverse-shell binaries IP address 77.110.126.46 Secondary controller embedded in Go reverse-shell binaries IP address 77.110.122.137 Case-observed Gentlemen infrastructure IP address 77.110.122.58 Staging server associated with cons1.0.1.msi IP address 38.110.228.43 Historical resolution for wiselystarting.com IP address 38.110.228.125 Historical resolution for itemrange.com IP address 38.110.228.33 Open directory containing disclosed Gentlemen victim artifacts IP address 185.117.72.215 Historical resolution for resumeacceptable.com IP address 185.45.193.151 Historical resolution for publisherresolution.com IP address 50.114.167.112 Historical resolution for simultaneouslypower.com Domain itemrange.com Historical EtherRAT C2 domain from the Ethereum contract Domain wiselystarting.com Historical EtherRAT C2 domain from the Ethereum contract Domain simultaneouslypower.com Historical EtherRAT C2 domain from the Ethereum contract Domain resumeacceptable.com Historical EtherRAT C2 domain from the Ethereum contract Domain publisherresolution.com Historical EtherRAT C2 domain from the Ethereum contract URL hxxp://193.233.202.17:42718/task39.ps1 PowerShell payload download location URL hxxp://193.233.202.17:8088/slvbeaconsc.bin Sliver shellcode download location URL hxxps://193.233.202.17 Sliver C2 endpoint Ethereum contract 0xb3f2897f2bc797e5b9033faef8c81e92b01cb831 EtherRAT C2 resolver contract Ethereum lookup key 0x40b57c3622c1CbfD699207F71F2dE5A8Fe256893 Smart-contract lookup key HTTP header X-Bot-Server EtherRAT network detection indicator File name consc1.0.1.msi EtherRAT installer deployed by remote scheduled tasks SHA-256 EE6807A8ABFABCED22EE026E178A28DA64D13CC3408E224394FF6E5782FB9E1D Hash of consc1.0.1.msi File name jEdb5ROX.cmd Node.js bootstrapper installed by the EtherRAT MSI SHA-256 F659681525DEBDA69FE0865B2B27A42F684B1FDA66AA7398E80B84CC765C73C7 Hash of jEdb5ROX.cmd File name YUGKag9mvNKWylo.bin EtherRAT decoder and Run-key persistence component SHA-256 7567994310A9576B1F98DC672ECFA038F1D65084315F59E3883F9B6F24000073 Hash of YUGKag9mvNKWylo.bin File name jlfYWzAkN99jpGu.xml XOR-encrypted EtherRAT backdoor SHA-256 73955566338ADFFB423C3B7608792963080DA780E8B7B2C2CD6B6B0CEF6F217F Hash of jlfYWzAkN99jpGu.xml File name BDQbS2lZ6u.bak Decoded Node.js EtherRAT payload SHA-256 86881B8E9D197AC2F734792DE48D5DFAEBE7CAFB6E35D49C5DD7FE6EB697230E Hash of BDQbS2lZ6u.bak File name task39.ps1 Account creation, defence impairment, hive theft, tunnelling, and reverse-shell script Hash F609621698EAAD8C4683750FE8BD0E2423 Hash listed for task39.ps1 File name slvbeaconsc.bin SGN/Donut-packed Sliver beacon shellcode SHA-256 FB94688ED37DFCB985A8A4D720230E5150956E1788D579B0A54B53A153FD2F2E Hash of slvbeaconsc.bin File name VOCATIONALGORILLA Sliver implant extracted from shellcode SHA-256 C7A80576FBD25057435652788591D13998DA272EDF627FC29D296684CEFC50E5 Hash of...












